GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,681
Maven
5,000+
npm
4,311
NuGet
760
pip
4,084
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
115 advisories
Filter by severity
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
GHSA-q7jf-gf43-6x6p
was published
for
hono
(npm)
Oct 24, 2025
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This...
Moderate
Unreviewed
CVE-2025-12642
was published
Nov 3, 2025
The team has identified a critical vulnerability in the http server of the most recent version of...
Moderate
Unreviewed
CVE-2024-27982
was published
May 7, 2024
Puma's header normalization allows for client to clobber proxy set headers
Moderate
CVE-2024-45614
was published
for
puma
(RubyGems)
Sep 20, 2024
twisted.web has disordered HTTP pipeline response
Moderate
CVE-2024-41671
was published
for
twisted
(pip)
Jul 29, 2024
Puma HTTP Request/Response Smuggling vulnerability
Moderate
CVE-2024-21647
was published
for
puma
(RubyGems)
Jan 8, 2024
twisted.web has disordered HTTP pipeline response
Moderate
CVE-2023-46137
was published
for
twisted
(pip)
Oct 25, 2023
Eventlet affected by HTTP request smuggling in unparsed trailers
Moderate
CVE-2025-58068
was published
for
eventlet
(pip)
Aug 29, 2025
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
Moderate
CVE-2024-52304
was published
for
aiohttp
(pip)
Nov 18, 2024
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
Moderate
CVE-2024-23829
was published
for
aiohttp
(pip)
Jan 29, 2024
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
Moderate
CVE-2023-47627
was published
for
aiohttp
(pip)
Nov 14, 2023
Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled...
Moderate
Unreviewed
CVE-2025-11915
was published
Oct 22, 2025
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard...
Moderate
Unreviewed
CVE-2025-6999
was published
Sep 16, 2025
Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an...
Moderate
Unreviewed
CVE-2025-54142
was published
Aug 29, 2025
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
Moderate
GHSA-63cx-g855-hvv4
was published
for
mitmproxy
(pip)
Aug 25, 2025
An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26....
Moderate
Unreviewed
CVE-2025-32094
was published
Aug 7, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
Moderate
CVE-2025-6442
was published
for
webrick
(RubyGems)
Jun 26, 2025
Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow...
Moderate
Unreviewed
CVE-2025-47905
was published
May 14, 2025
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX`...
Moderate
Unreviewed
CVE-2025-23167
was published
May 19, 2025
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module...
Moderate
Unreviewed
CVE-2020-11993
was published
May 24, 2022
CVE-2025-1386- Query smuggling in ch-go library
Moderate
CVE-2025-1386
was published
for
github.com/ClickHouse/ch-go
(Go)
Apr 12, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via...
Moderate
Unreviewed
CVE-2025-30346
was published
Mar 21, 2025
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack...
Moderate
Unreviewed
CVE-2022-39163
was published
Mar 26, 2025
ProTip!
Advisories are also available from the
GraphQL API